WEB APPLICATION PENETRATION TESTING

Find the flaws in your web app before someone else does.

Your web application is where your customers, your revenue and your regulated data all meet, which is exactly why it is the first thing a serious attacker studies. We test it by hand: the authorisation logic, the multi-step business flows, the chained exploits a scanner will never reach. You get every finding proven with a working exploit, ranked by what it would actually cost you, and retested until it is closed.

How a web pentest works
87%
of our clients renew annually
150+
organisations across multiple European countries
7/10
confirm findings their previous provider did not find
Want to audit your company’s applications?

Protected by reCAPTCHA. The Google Privacy Policy and Terms of Service apply.

Trusted by companies in highly regulated environments

Watch what a real attacker would do to your web app.

Autenticada como · [email protected]
GET /api/orders/4813
↳ el atacante cambia el ID: el servidor no comprueba nada más
ID manipulado
API · orders IDOR
200 OK DATOS DE OTRO CLIENTE
order_id4813
total€12,840.00
card_last4•••• 7421
↳ El servidor ha devuelto el pedido de otro cliente. Control de acceso roto.
Misma sesión · recorridos los ids 4801-4840 37 de 40 respondieron
idcustomertotalpropietario
4812[email protected]€188.50suyo
4813[email protected]€12,840.00no es suyo
4814[email protected]€2,306.20no es suyo
4815[email protected]€41,915.00no es suyo
… 33 ids más respondieron igual
IMPACTOFalta una comprobación de propiedad: todo el libro de pedidos

Give a scanner your login page and it returns a missing security header. Give us the same login page and we return the order belonging to another one of your customers. That gap, between what a tool reports and what an attacker reaches, is why a manual pentest exists.

The flaws that cause real incidents rarely sit in a signature database. They live in your authorisation logic and your multi-step business flows. We reproduce each one, chain them where a chain exists, and hand your engineers the exact request, payload and fix path.

WHAT WE AUDIT
  • Authentication and session management
  • Authorisation and access control (BOLA, BFLA, privilege escalation)
  • Business logic and multi-step transaction flows
  • Input validation, injection and output handling
  • APIs (REST, GraphQL) and their authorisation model
  • File handling, uploads and deserialisation
  • Server-side request forgery and cloud metadata exposure
  • Configuration, secrets exposure and security headers

Why a CTO, CISO or CIO books a web pentest.

The trigger is a product launch, an audit clause, an enterprise customer’s security questionnaire, a board question, or an incident in your sector that made the risk suddenly concrete.

TAP A SITUATION
Compliance & audit ISO 27001 audit window

An auditor does not accept a marketing PDF, and neither does an enterprise procurement team.

With ISO 27001, ENS, PCI DSS or SOC 2 on the line, the report has to survive scrutiny: traceable scope, methodology mapped to a recognised standard, signed retest and an execution certificate for the auditor folder.

  • Methodology mapped to PTES, NIST SP 800‑115, OWASP WSTG and OWASP API Security Top 10
  • Execution certificate ready for the auditor folder
  • Retest evidence with timestamps and signoff
  • Scope and Rules of Engagement documented before testing starts
Board & customer Board asked for assurance

Someone with authority asked, and ‘we’re fine’ isn’t an answer.

When the ask is for assurance, you need an external, expert-led engagement and a deliverable that maps to business impact in language a non-technical stakeholder can read.

  • Executive summary that lands without translation
  • Findings ranked by business impact and audit exposure
  • Attestation language that satisfies enterprise procurement
  • Independence: external and expert-led throughout
Release & change Pre-launch hardening

You are shipping something new, and it cannot break in production.

Every new surface ships with its own threat model. We test it before it is live, against the authorisation and tenancy logic a scanner cannot reason about, and retest after the fix so the release closes clean.

  • Threat model written for the surface shipping, not a generic checklist
  • Authorisation, tenancy and session boundaries pressure-tested by hand
  • Critical findings reported live, so fixes happen before launch
  • Same operator across test and retest, so no context is lost
Incident-driven Recent breach in your sector

Something happened. You need to know what is still exposed.

The question is not ‘do we have findings’ but ‘are there other paths’. We confirm the route that was used, or feared, is closed, and surface every adjacent vulnerability an attacker could pivot to.

  • Targeted scope around the suspected attack path
  • Adjacent surface mapped: authorisation, sessions, APIs, admin functionality
  • Reproducible proofs of concept for the incident-response team
  • Live findings to your responders, not the final report
Business event M&A technical due diligence

A transaction or a handover put the application under new eyes.

We test the application the way the other side of the table would, so what you are taking on is evidence rather than an assurance, and the first serious finding does not arrive after the paperwork is signed.

  • Scope agreed against the application as it is, not as the documentation describes it
  • Every finding proven with a working exploit, not a scanner severity
  • Ranked by what it would actually cost, in language a non-technical reader follows
  • Retest to closure, so the handover ends with the gaps closed

Ready to see what we would find in yours?

Seven phases. The same shape your auditor expects.

Seven phases, the way we actually run them against a web application. The short version is below; your stack and its business context decide the path we take through it.

What you actually get, and why it is different.

Most web pentests fail in one of four predictable ways. Here is how we close each gap.

Validated by a human, not flagged by a tool

A senior specialist reproduces every finding by hand, so what reaches your report is real, exploitable and worth fixing.

Ranked by business impact, not just CVSS

A medium-severity IDOR that exposes your customer table is a board problem, whatever CVSS says. We rank by what it costs you.

A report two audiences can use

One document, no translation layer: a summary a CIO can take upward, and the request, payload and fix a developer can act on.

Closed, not just reported

The retest is included, at no cost and with no time limit, tracked live in our platform, not buried in a PDF nobody reopens.

Want to see what your next pentest with us would look like?

We at Etnia highly value our collaboration with Asperis Security.
Sergi Leno, Systems Manager · ETNIA Barcelona

Loved by engineering and security teams.

Names, roles and companies on the record.

We at Etnia highly value our collaboration with Asperis Security. Their professionalism, approachability, quick response and ability to adapt to our needs have been key in every project. The quality of service and continuous support always give us peace of mind. Without a doubt, it is a pleasure to have them as technology partners.
Sergi Leno, Systems Manager
ETNIA Barcelona
ASPERIS has worked alongside us to define and implement our cybersecurity roadmap in Microsoft 365 with a structured approach aligned to business objectives. Thanks to their advice, we took the strategic step of completing our Microsoft ecosystem and reinforcing it with CrowdStrike for advanced mobile device protection, significantly raising our security level.
Jordi Bondia, IT Director
SALVI
At NPAW we have collaborated with Asperis on various security initiatives and the experience has been very positive. We especially value their ability to adapt to our needs and the depth with which they approach each project. Results are clear, structured and useful for decision-making and continuous security improvement. We like working with Asperis for the judgment and value they bring to every collaboration. Their work has helped us strengthen our security level.
Sergi Laencina Verdaguer, CISO
NPAW
With Asperis you don’t hire a service. You hire a partner. They don’t look to bill a project. They look to establish a relationship of trust, caring about the key points that affect your organisation’s security. Professionalism, know-how and diligence.
Juan Valer Tecedor, Software Engineer
GNOSS
READY WHEN YOU ARE

Want a real pentest scope for your stack?

Tell us what you would like tested. An experienced consultant replies with a tailored scope, a fixed quote and a timeline.

Questions that come up before signing.

A scanner matches your application against a database of known patterns and returns a list, most of it false positives, none of it interpreted. A pentest is a person reasoning about your specific application: reconnaissance, controlled exploitation, and the business-context judgement to know that a predictable order ID plus a missing authorisation check equals your entire customer table. The deliverable is a short list of findings that are genuinely exploitable in your environment, ranked by impact, each with a reproducible proof of concept. We use scanners to accelerate coverage during reconnaissance. We never ship you their output as the report.

Not without your explicit consent. Every engagement ships with documented Rules of Engagement: test windows, permitted intensity, forbidden actions and kill-switch contacts. In most cases we test a staging environment or a production mirror, and touch production only for read-only reconnaissance or explicitly authorised paths. Where exploitation in production is agreed, it runs under agreed rate limits with your team on standby, and we abort anything that risks availability.

Price follows scope, complexity and test type (black box, grey box or white box). We deliver a fixed-price proposal within 48 hours of the first call, with no hidden fees and no obligation to renew. A focused audit of a single application sits at the bottom of the range. Larger multi-tenant SaaS platforms or complex API estates scale from there. The retest is always included in the price.

Less than most teams expect. For a grey-box engagement, the usual choice, we ask for two test users per role, access to a staging environment or the production URL in scope, API documentation if you have it, and one technical contact for questions during the test. We bring the test data, tooling and reporting. A white-box engagement adds source-code access under NDA.

The specialist you meet on the first call. Our team holds OSCP, OSWE, OSEP, CRTO and CRTP credentials, most have worked inside enterprise security teams or research-led red teams, and we are NASA Bug Bounty verified contributors with published CVEs against widely deployed software. Your engagement is scoped, executed and retested by the same person throughout. That is who you speak to at every stage.

Annually as a compliance floor for ISO 27001, ENS, PCI DSS and SOC 2. In practice, cadence should follow how fast your application changes: teams shipping weekly benefit from continuous testing through the platform rather than a single yearly engagement. A fresh test is also warranted by any material change: a new authentication or SSO integration, a new B2B or admin portal, a first AI feature reaching production, or an incident in your sector.

Ready to protect your application?

We will review your attack surface, understand the business context around it, and define the right web pentest before the engagement begins.

Request a web pentest proposal.
An experienced web pentester replies within one business day.

Protected by reCAPTCHA. The Google Privacy Policy and Terms of Service apply.

Or email [email protected] directly.

OUR CLIENTS HAVE ALREADY DONE IT

We at Etnia highly value our collaboration with Asperis Security.

Sergi Leno, Systems Manager
ETNIA Barcelona

ASPERIS has worked alongside us to define and implement our cybersecurity roadmap in Microsoft 365 with a structured approach aligned to business objectives.

Jordi Bondia, IT Director
SALVI

At NPAW we have collaborated with Asperis on various security initiatives and the experience has been very positive.

Sergi Laencina Verdaguer, CISO
NPAW

With Asperis you don’t hire a service. You hire a partner.